Page 1 of 1

CDM Assessment

20 quick questions on your security maturity. Rate each on a 0–4 scale: 0 = Not in place · 1 = Ad hoc · 2 = Partial · 3 = Mostly · 4 = Fully / optimized.

About you & your organization

First name

Last name

Company name

Business email

Phone

Website

Company size

Organization type

Primary pain point

Compliance need

Identify

Devices: comprehensive, up-to-date inventory of all hardware (workstations, servers, mobile, IoT, BYOD)

Devices: comprehensive, up-to-date inventory of all hardware (workstations, servers, mobile, IoT, BYOD)
Not in placeFully / optimized

Applications: maturity of inventorying all software/applications (versions, data flows, dependencies)

Applications: maturity of inventorying all software/applications (versions, data flows, dependencies)
Not in placeFully / optimized

Networks: extent authorized network communication paths and data flows are mapped, baselined, visualized

Networks: extent authorized network communication paths and data flows are mapped, baselined, visualized
Not in placeFully / optimized

Data: completeness/accuracy of inventorying, classifying, and prioritizing sensitive data across all locations

Data: completeness/accuracy of inventorying, classifying, and prioritizing sensitive data across all locations
Not in placeFully / optimized

Users: authoritative directory of all user identities (roles, access levels, privileges)

Users: authoritative directory of all user identities (roles, access levels, privileges)
Not in placeFully / optimized

Protect

Devices: consistency of preventative controls (hardening, patching, EDR) across managed devices

Devices: consistency of preventative controls (hardening, patching, EDR) across managed devices
Not in placeFully / optimized

Applications: maturity of application safeguards (secure SDLC, WAF, RASP)

Applications: maturity of application safeguards (secure SDLC, WAF, RASP)
Not in placeFully / optimized

Networks: use of segmentation, micro-segmentation, and Zero Trust to limit unauthorized comms and contain breaches

Networks: use of segmentation, micro-segmentation, and Zero Trust to limit unauthorized comms and contain breaches
Not in placeFully / optimized

Data: effectiveness of technical controls (encryption, DLP) protecting sensitive data

Data: effectiveness of technical controls (encryption, DLP) protecting sensitive data
Not in placeFully / optimized

Users: effectiveness of awareness training and identity policies (MFA, least privilege) in reducing human risk

Users: effectiveness of awareness training and identity policies (MFA, least privilege) in reducing human risk
Not in placeFully / optimized

Detect

Devices: use of continuous monitoring (EDR) to detect anomalies and indicators of compromise on devices

Devices: use of continuous monitoring (EDR) to detect anomalies and indicators of compromise on devices
Not in placeFully / optimized

Applications: how effectively application logs and events are correlated/analyzed (SIEM) to detect anomalous behavior

Applications: how effectively application logs and events are correlated/analyzed (SIEM) to detect anomalous behavior
Not in placeFully / optimized

Networks: capability to monitor traffic for anomalies and hunt intrusions (NDR/IDS)

Networks: capability to monitor traffic for anomalies and hunt intrusions (NDR/IDS)
Not in placeFully / optimized

Data: maturity of detecting data breaches (access-log analysis, unusual movement, provenance)

Data: maturity of detecting data breaches (access-log analysis, unusual movement, provenance)
Not in placeFully / optimized

Users: use of UEBA or similar to detect anomalous user behavior, compromised credentials, insider threats

Users: use of UEBA or similar to detect anomalous user behavior, compromised credentials, insider threats
Not in placeFully / optimized

Respond & Recover

Devices: maturity and tested effectiveness of responding to a compromised device (containment, eradication, clean restore)

Devices: maturity and tested effectiveness of responding to a compromised device (containment, eradication, clean restore)
Not in placeFully / optimized

Applications: preparedness to respond to a compromised application (isolate, assess, recover with minimal interruption)

Applications: preparedness to respond to a compromised application (isolate, assess, recover with minimal interruption)
Not in placeFully / optimized

Networks: how well-defined and rehearsed the incident-response plan is for a network intrusion

Networks: how well-defined and rehearsed the incident-response plan is for a network intrusion
Not in placeFully / optimized

Data: ability to respond to and recover from a data breach (damage assessment, integrity restore, stakeholder comms)

Data: ability to respond to and recover from a data breach (damage assessment, integrity restore, stakeholder comms)
Not in placeFully / optimized

Users: preparedness to respond to a compromised account or insider threat (revocation, investigation, recovery)

Users: preparedness to respond to a compromised account or insider threat (revocation, investigation, recovery)
Not in placeFully / optimized